4 ms·
Does it actually work though? It seems like there is a significant difference between the expectation that semantic versioning should result in no disruption,
by stanferder 7y ago
Does it actually work though? It seems like there is a significant difference between the expectation that semantic versioning should result in no disruption, and the experience of the parent to your comment. I'd be interested to know exactly what went wrong that lead that poster to be pessimistic.
- jiveturkey 7y agoYes it does actually work and has for decades. The poster is either confused or doing something different, I expect. The specific notice mentions rust dependencies. Rust does not have shared libraries, so a Rust [security] update means all rust binaries must be completely rebuilt. That seems to be part of OpenBSD's concern, and perhaps this has "triggered" the poster. user blackhaz random forum post found: > mariourk, you're definitely not alone. The same breakage happens to FreeBSD desktops as well. I have been vocal around the forum a few times about this. Not every desktop user wants to upgrade all their packages every X months. The way the default repositories are structured, the upgrades are forced onto users. I am a huge proponent of using application bundles, like on Mac OS, as quite often those upgrades break complex desktop apps too. I don't mind upgrades but sometimes I need to stick with a specific version of software, or roll back after something went wrong, and if it came as a bundle with its own dependencies, it wouldn't have to depend on other stuff that is being "force-upgraded" periodically. So his complaint is about the way FBSD handles updates; he is generally incorrect about shared libraries; and his comment is completely OT for this thread.
- zozbot234 7y ago> Rust does not have shared libraries, so a Rust [security] update means all rust binaries must be completely rebuilt. What's the concern with that, exactly? OpenBSD is a security-focused distribution, do they not do reproducible builds?
- Conan_Kudo 7y agoBecause rebuilding everything all the bloody time is expensive. Virtually every Linux distribution and BSD share this concern. We've all complained about it to Rust upstream, but they don't care. To them, it's cheap to rebuild every Rust project every time the compiler is updated or the standard library needs a fix. See for yourself: https://github.com/rust-lang/rfcs/issues/600 https://github.com/rust-lang/rfcs/issues/600 What's worse is that a lot of people are forgetting why we do it this way in the first place. While part of it was about saving disk space, the major reason we do this is for being able to fix things in a cheap way and have wide-ranging impact. Without this, things like security fixes to zlib, libvpx, or other important libraries would require finding all their reverse dependencies, patching them, and rebuilding them to incorporate the fixes. It's incredibly important, but because nobody cares in Rust and Mozilla, we're all doomed...
- deleted 7y ago[deleted]
- Rusky 7y ago> Rust does not have shared libraries Nonsense. Rust has shared libraries just as much as C and C++ do. Distributions can and do build individual Rust crates as shared libraries, and crate authors can go further and offer a shared library with a C ABI that remains stable across rustc versions. (The latter is what cbindgen is for.) The problem here is that the maintainers don't want to keep multiple versions of a crate around, so when any single application uses a newer version it forces an update on all the rest. Which is exactly what Rust's tendency toward static linking avoids.
- zozbot234 7y agoIt's not that simple. New versions of Firefox can require a higher minimum version for the Rust compiler, and upgrading that will break the ABI for all crates that don't stick to a pure C ABI, regardless of shared vs. static linking,